Releases21
Frequency2 months 3 weeks
Last Release
Regular expression for matching URLs

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
all versions, <= 1.0.45.3 MEDIUM5 MEDIUM

All versions of package url-regex are vulnerable to Regular Expression Denial of Service (ReDoS) which can cause the CPU usage to crash.

all versions, <= 5.0.07.5 HIGH7.8 HIGH

all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.